Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
13.812 exploits
GitHub PoC4
CVE-2019-0708, A tool which mass hunts for bluekeep vulnerability for exploitation.
CVE-2019-0708CRITICALsob ataqueransomware17 set 2022
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RISCO
abrir
GitHub PoC1
pswalia2u/CVE-2020-7246
CVE-2020-724616 set 2022
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RISCO
abrir
GitHub PoC
cve-2010-2553复现
CVE-2010-255316 set 2022
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISCO
abrir
GitHub PoC
CVE-2022-37204 POC
CVE-2022-37204CRITICAL15 set 2022
Final CMS 5.1.0 is vulnerable to SQL Injection.
48RISCO
abrir
GitHub PoC2
A proof of concept for CVE-2022-30190 (Follina).
CVE-2022-30190HIGHsob ataqueransomware15 set 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
100RISCO
abrir
GitHub PoC1
kernel-cyber/CVE-2009-4623
CVE-2009-462315 set 2022
Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbi
23RISCO
abrir
GitHub PoC
mightysai1997/cve-2021-42013
CVE-2021-42013CRITICALsob ataqueransomware15 set 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
mightysai1997/cve-2021-42013L
CVE-2021-42013CRITICALsob ataqueransomware15 set 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC
mightysai1997/cve-2021-42013.get
CVE-2021-42013CRITICALsob ataqueransomware15 set 2022
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISCO
abrir
GitHub PoC2
dhammon/pfBlockerNg-CVE-2022-40624
CVE-2022-40624CRITICAL15 set 2022
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host
68RISCO
abrir
GitHub PoC
mightysai1997/CVE-2021-41773.git1
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
mightysai1997/cve-2021-41773-v-
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
mightysai1997/CVE-2021-41773-L-
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
mightysai1997/CVE-2021-41773m
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
mightysai1997/CVE-2021-41773h
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
mightysai1997/CVE-2021-41773S
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
mightysai1997/CVE-2021-41773-i-
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
mightysai1997/cve-2021-41773
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC
mightysai1997/CVE-2021-41773-PoC
CVE-2021-41773HIGHsob ataqueransomware15 set 2022
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISCO
abrir
GitHub PoC1
Free MP3 CD Ripper 2.6 版本中存在栈缓冲区溢出漏洞 (CVE-2019-9766),远程攻击者可借助特制的 .mp3 文件利用该漏洞执行任意代码。
CVE-2019-976614 set 2022
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RISCO
abrir
GitHub PoC5
CVE-2022-34715-POC pcap
CVE-2022-34715CRITICAL13 set 2022
Windows Network File System Remote Code Execution Vulnerability
70RISCO
abrir
GitHub PoC2
bl4ck574r/CVE-2019-17662
CVE-2019-1766213 set 2022
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RISCO
abrir
GitHub PoC
ApacheSolrRCE(CVE-2019-0193)一键写shell,原理是通过代码执行的java文件流写的马。
CVE-2019-0193HIGHsob ataque13 set 2022
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources,
100RISCO
abrir
GitHub PoC7
Automation to validate the impact of the vulnerability CVE-2022-1292 on a specific system.
CVE-2022-1292CRITICAL13 set 2022
The c_rehash script allows command injection
70RISCO
abrir
GitHub PoC3
CVE-2022-27925 nuclei template
CVE-2022-27925HIGHsob ataqueransomware12 set 2022
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
100RISCO
abrir
GitHub PoC323
A reliable exploit + write-up to elevate privileges to root. (Tested on Ubuntu 22.04)
CVE-2022-37706HIGH12 set 2022
enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and th
56RISCO
abrir
GitHub PoC1
M4fiaB0y/CVE-2022-30075
CVE-2022-3007512 set 2022
In TP-Link Router AX50 firmware 210730 and older, import of a malicious backup file via web interface can lead to remote
35RISCO
abrir
GitHub PoC8
POC exploit for CVE-2015-4133
CVE-2015-413312 set 2022
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RISCO
abrir
GitHub PoC2
CVE-2022-0847(Dirty Pipe) vulnerability exploits.
CVE-2022-0847HIGHsob ataque11 set 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RISCO
abrir
GitHub PoC4
CVE-2021-38163 - exploit for SAP Netveawer
CVE-2021-38163CRITICALsob ataque10 set 2022
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated
90RISCO
abrir
anteriorpágina 300 / 461próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.